Cybersecurity Consultant specialized in Governance, Risk and Compliance (GRC), I support organizations in managing their information security and cyber risk governance.

Gary Alexis Grivault

Cybersecurity Consultant specialized in Governance, Risk and Compliance (GRC), I support organizations in managing their information security and cyber risk governance.

Available to hire

Cybersecurity Consultant specialized in Governance, Risk and Compliance (GRC), I support organizations in managing their information security and cyber risk governance.

Experience Level

Intermediate
Intermediate
Intermediate

Language

French
Fluent
English
Advanced

Work Experience

Security Engagement Manager at CGI BUTACHIMIE
November 24, 2022 - Present
Monitored security maintenance, conducted Cybersecurity Awareness Training for group employees, performed risk assessment and reevaluation. Conducted ASP, EBIOS RM risk analysis (Aug 24 to Nov 24) and planned committees and project monitoring for EBIOS RM (Workshops 1 to 5). Prepared workshop materials and deliverables and participated in the development of the final summary deliverable.
Cybersecurity Awareness Program Lead at LIMAGRAIN
July 23, 2023 - Present
Planned and monitored the CAP 23-24 program for 10,000 employees. Conducted and facilitated steering committee meetings. Led and framed the group’s cybersecurity awareness project. Created and disseminated cybersecurity awareness materials in multiple languages. Introduced new CYBER indicators and consolidated them for management purposes.
Program Monitoring Specialist – Free Flow at APRR
May 1, 2022 - December 31, 2023
Monitored action plans within a strategic business program (risk analysis, penetration testing, code audits, configuration audits). Coordinated and oversaw compliance with third-party vendors. Planned steering committees, coordinating security audits.
Shared CISO at SITIV
April 1, 2021 - April 1, 2022
Developed a shared Information System Security Policy for SITIV + 8 member municipalities. Completed ANSSI cybersecurity journey: organizational and technical situation assessment. Contributed to the security plan (penetration tests, firewall configuration audits). Implemented remediation measures. Secured Active Directory domains, conducted EBIOS RM risk analysis, established a security incident management plan, formed a security referents working group, monitored IT vulnerabilities, and participated in collaborative events.
IT Recruitment Consultant at MANPOWER France
January 1, 2016 - April 1, 2020
IT recruitment consultant focusing on IT staffing and talent acquisition.
IT Business Manager at MANPOWER France
January 1, 2011 - December 31, 2015
Managed IT business operations and client relationships.

Education

BAC+5 Expert en Sécurité Digitale at IT Akademy Lyon
December 1, 2020 - December 1, 2021
Gouvernance Risques et Conformité, sécurité globale du SI, tests d'intrusion, analyse forensics, audit, ethical hacking at IT Akademy Lyon
January 11, 2030 - February 27, 2026
Advanced Technician’s Certificate in Industrial Computing at Lycée Edouard BRANLY
September 5, 1999 - July 5, 2001

Qualifications

Microsoft Azure Fundamentals (AZ-900)
October 1, 2020 - February 27, 2026
Piloter un projet: les fondamentaux
January 1, 2019 - February 27, 2026
Master’s degree in digital security
July 11, 2020 - January 1, 2021
Tenancy Certified Partner
January 11, 2030 - January 1, 2024
Microsoft Azure Security – AZ500
January 11, 2030 - February 27, 2026
ISO 27001 Lead Implementer
January 11, 2030 - February 27, 2026
EBIOS Risk Manager
January 1, 2023 - February 27, 2026
Microsoft Azure Fundamentals – AZ900
January 1, 2020 - February 1, 2020
BULATS C1
January 1, 2017 - December 31, 2017
Microsoft Certified System Administrator
January 1, 2003 - December 31, 2003

Industry Experience

Manufacturing, Transportation & Logistics, Government, Professional Services, Software & Internet
    paper Security Governance for an Innovative Tolling Project

    🚧 Security Governance – Barrier-Free Tolling Project (OIV) | APRR

    🎯 Context

    Led the security governance of a large-scale barrier-free tolling project at APRR (Operator of Vital Importance), covering France and Austria, in a highly exposed environment subject to ANSSI regulatory requirements.

    🛡️ Governance, Risk & Compliance

    • Oversaw action plans resulting from ISO 27001 audits
    • Managed PCI DSS SAQ-A self-assessment in coordination with the external auditor
    • Updated and maintained project-wide risk assessments
    • Ensured continuous alignment with regulatory and compliance requirements

    🤝 Stakeholder & Security Coordination

    • Facilitated security committees (COPIL) with:
      • Infrastructure teams
      • Application teams
      • Operations teams
      • Third-party providers
    • Ensured stakeholder alignment on security priorities and risk mitigation
    • Supported secure integration of new architectures and exposed data flows

    📊 Security Steering & Monitoring

    • Structured governance KPIs and security indicators
    • Built monitoring dashboards for executive visibility
    • Provided regular steering committee reporting (COPIL)
    • Strengthened risk control and decision-making processes

    📈 Impact

    • Secured a critical and highly exposed infrastructure project (OIV scope)
    • Improved governance, compliance, and risk visibility at project scale
    • Enabled structured security oversight across multi-country operations
    • Reinforced alignment with ANSSI, ISO 27001, and PCI DSS requirements
    paper Cyber Governance & Security Culture at Scale

    🌍 Global Cybersecurity Awareness Program – Limagrain (10,000+ Employees)

    🎯 Context

    Led the international Cybersecurity Awareness Program across a multi-country environment, covering over 10,000 employees and supporting the organization’s security culture at scale.

    🧭 Governance & Program Management

    • Aligned the program with ISO 27001 and CIS Controls
    • Managed the migration of the e-learning platform (PSAT → 360Learning)
    • Coordinated with internal teams and instructional engineering stakeholders
    • Facilitated steering committees (COPIL) and governance follow-ups

    📊 Monitoring & Performance Management

    • Defined and structured key KPIs:
      • Completion rates
      • Campaign performance
      • Population coverage
    • Built dashboards and ensured regular reporting for executive decision-making
    • Tracked deployment progress and program effectiveness

    🌐 International Deployment

    • Designed and adapted training materials in 19 languages
    • Ensured consistent and homogeneous rollout across multiple countries
    • Supported large-scale adoption of cybersecurity best practices

    📈 Impact

    • Strengthened cybersecurity culture at organizational scale
    • Improved compliance with ISO 27001-aligned awareness requirements
    • Established a structured, measurable, and sustainable awareness governance framework
    paper Structuring and Deployment of a Shared Information Security Framework for 8 Local Authorities

    🛡️ Shared CISO – Deployment of a Cybersecurity Framework for 8 Local Authorities (SITIV)

    🎯 Context

    Acted as a Shared CISO (RSSI) for SITIV and 8 member municipalities to structure and deploy a unified Information Security Management System (ISMS) for a shared information system.

    🔍 Key Responsibilities

    • Conducted EBIOS RM risk assessments
    • Prioritized cyber risks and defined mitigation strategies
    • Built a cybersecurity roadmap aligned with ANSSI guidelines
    • Structured and formalized IS governance framework (policies, procedures, incident management)
    • Facilitated the network of security representatives across municipalities
    • Coordinated with technical and operational teams

    🏗️ Governance & Security Deliverables

    • ISMS policies (PSSI)
    • Risk assessment reports (EBIOS RM)
    • Security procedures and governance model
    • Incident management framework
    • Cybersecurity roadmap & KPI tracking

    📈 Impact

    • Increased cybersecurity maturity across 8 local authorities
    • Secured shared and critical infrastructures
    • Established a sustainable and structured security governance model
    • Enabled long-term cyber risk management at organizational scale

Hire a Project Manager

We have the best project manager experts on Twine. Hire a project manager today.